IP Library Granted Patent US 9,111,092
Granted Patent B2
US 9,111,092 · App. 13/219,871 · Granted Aug 18, 2015

Security event management apparatus, systems, and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,111,092
App. No.
13/219,871
Granted
Aug 18, 2015
Kind
B2
Abstract

Apparatus, systems, and methods may operate to include transforming subsequent unmarked contexts into additional tainted contexts in response to identifying a tainted event as a link between a prior tainted context and the subsequent unmarked contexts. Further operations may include publishing an event horizon to a display. The event horizon may include the tainted event and all other events associated with a linked chain of contexts that include the prior tainted context and the additional tainted contexts, where the tainted event and the other events share the taint in common. In this way, a taint associated with malicious behavior can be propagated and tracked as it moves between contexts. Additional apparatus, systems, and methods are disclosed.

Claims (55)

1. A system, comprising:

an interface to receive an unmarked event, wherein an event is an action capable of being monitored and recorded within a computer system with one or more corresponding contexts for the event, the one or more corresponding contexts including information about an environment surrounding an interaction between a corresponding event and one or more functions provided by an application at a point-in-time;

at least one processor to:

transform the unmarked event into a tainted event by marking the unmarked event with a taint;

mark the one or more corresponding contexts for the event as tainted contexts using the taint;

mark a prior unmarked context associated with the tainted event with the taint to create a prior tainted context, so as to propagate the taint from the tainted context to the prior tainted context, propagation of the taint being time-limited;

mark any subsequent context linked to the prior tainted context by the tainted event or other events, as subsequent tainted contexts, so as to propagate the taint from the tainted context to the prior tainted context and then to the subsequent tainted contexts, propagation of the taint being time-limited; and

mark any other unmarked event emanating from the tainted contexts, the prior tainted context, or the subsequent tainted contexts as other tainted events with the taint; and

a display to publish an event horizon as part of a graphical user interface (GUI) executed by a client node, the event horizon including the tainted event and all of the other tainted events.

2. The system of claim 1 , further comprising a source of the unmarked event, the source comprising at least one of a server, a client, a storage node, hardware circuitry, or an application.

3. The system of claim 1 , further comprising:

data sinks in a memory to record the tainted event and at least some of the other events in a normalized format.

4. The system of claim 1 , further comprising:

a real time analysis engine to monitor interaction of one of the subsequent contexts with the tainted event.

5. The system of claim 4 , further comprising:

an event bus to transport at least one of the tainted event or the other events to and from the real time analysis engine.

6. A processor-implemented method to execute on one or more processors that perform the method, comprising:

receiving an indication that a context associated with a source of an event is malicious, wherein the context includes information about an environment surrounding an interaction between a corresponding event and one or more functions provided by an application at a point-in-time, and wherein the event is an action capable of being monitored and recorded within a computer;

generating a context taint to identify the context as a tainted context that is malicious when the context has not been previously known to be malicious;

transforming the event from an unmarked event to a tainted event by marking the unmarked event with the context taint;

marking a prior unmarked context associated with the tainted event with the taint to create a prior tainted context, so as to propagate the taint from the tainted context to the prior tainted context, propagation of the taint being time-limited;

marking any subsequent context linked to the prior tainted context by the tainted event or other events, as subsequent tainted contexts, so as to propagate the taint from the tainted context, to the prior tainted context, and then to the subsequent tainted contexts, propagation of the taint being time-limited;

marking any other unmarked event emanating from the tainted context, the prior tainted context, or the subsequent tainted contexts as other tainted events with the taint; and

publishing an event horizon to a display, the event horizon including the tainted event and all of the other tainted events.

7. The method of claim 6 , further comprising:

determining the source is malicious by matching static characteristics of the source with information in a policy defining malicious sources, the policy established prior to existence of the event.

8. The method of claim 6 , further comprising:

determining the source is malicious by matching malicious activity defined in a policy with activity presented by the source.

9. The method of claim 6 , wherein the receiving further comprises:

receiving the indication as a message from a software application, with respect to the source being another application compromised by a software virus.

10. The method of claim 6 , further comprising:

creating the taint to include a universally unique identifier (UUID) value.

11. The method of claim 6 , wherein the transforming further comprises:

applying the taint as a value that travels with the tainted event.

12. The method of claim 6 , wherein the marking further comprises:

applying the taint as a value that is associated with the context, the prior context, and the subsequent contexts, wherein the taint is not data to be processed within the context, the prior context, or the subsequent contexts.

13. A processor-implemented method to execute on one or more processors that perform the method, comprising:

receiving an indication that a context associated with a source of an event is malicious, wherein the context includes information about an environment surrounding an interaction between a corresponding event and one or more functions provided by an application at a point-in-time, and wherein the event is an action capable of being monitored and recorded within a computer;

transforming the event from an unmarked event to a tainted event by marking the unmarked event with the context taint;

marking a prior unmarked context associated with the tainted event with the taint to create a prior tainted context, so as to propagate the taint from the tainted context to the prior tainted context, propagation of the taint being time-limited;

transforming any subsequent unmarked contexts into additional tainted contexts in response to identifying the tainted event as a link between the prior tainted context and the subsequent unmarked contexts;

marking any other unmarked event emanating from the prior tainted context and the additional tainted contexts as other tainted events with a common taint; and

publishing an event horizon to a display, the event horizon including the tainted event and all of the other tainted events.

14. The method of claim 13 , further comprising:

verifying security assertions from user defined policies associated it the prior tainte context the additional tainted contexts.

15. The method of claim 14 , wherein the verifying comprises:

determining whether the taint applied to the tainted event is traveling toward a forbidden destination, or that the taint has reached the forbidden destination.

16. The method of claim 13 , further comprising:

blocking interaction of an event with a new context when the event is marked by the taint.

17. The method of claim 13 , wherein the transforming further comprises:

transforming the subsequent unmarked contexts into the additional tainted contexts for a time period defined by receiving an indication of manual termination, or by a self-terminating configuration value.

18. The method of claim 13 , wherein the transforming further comprises:

transforming the subsequent unmarked contexts into the additional tainted contexts across multiple computer systems without accessing a set of rules defining interactions between the multiple computer systems.

19. The method of claim 14 , further comprising:

responding to at least one of the security assertions according to a vulnerability category associated with at least one of the additional tainted contexts.

Assignments (12)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2012
From: APOSTOLESCU, PAUL; ANTONY, JOHN MELVIN; SRINIVASAN, PATTABIRAMAN
To: NOVELL, INC.
Reel/Frame 029025/0069 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
GRANT OF PATENT SECURITY INTEREST Recorded Nov 29, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 027289/0727 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded Nov 29, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 027290/0983 →